← Back to Daily Briefing (#ownCloud)

Nimbus Manticore, an IRGC-affiliated threat actor, has evolved its 2026 espionage operations by deploying a modified TWOSTROKE-variant backdoor and a custom Reverse SSH Tunneling utility to bypass network perimeter defenses. These tools, alongside the Minifast backdoor, utilize SSH-based exfiltration and tunneling protocols to establish persistent, covert Command and Control (C2) channels. The group leverages infrastructure historically linked to the Tortoiseshell actor profile to target high-value geopolitical entities, shifting toward a modular architecture to evade signature-based detection and increase operational tempo.

  • Campaign Overview: Strategic Evolution

    • IRGC-affiliated actor Nimbus Manticore is shifting toward modular toolsets to enhance espionage capabilities in 2026.
    • Transition from legacy tools to customized variants indicates increased resource investment and development sophistication.
    • Operations focus on high-value geopolitical targets relevant to Iranian state interests.
  • Technical Analysis: The Malware Toolset

    • Deployment of a TWOSTROKE-variant backdoor, utilizing modified code to evade traditional antivirus and EDR signatures.
    • Integration of the Minifast backdoor, as identified in Broadcom security bulletins, for initial access and persistence.
    • Use of customized Reverse SSH Tunneling utilities to encapsulate C2 traffic and mask unauthorized outbound connections.
  • Network Evasion: Reverse SSH Tunneling

    • Implementation of reverse tunnels to bypass restrictive firewall egress rules and network perimeter defenses.
    • Use of SSH-based exfiltration protocols to blend malicious data transfers with legitimate administrative traffic.
    • Strategic reliance on infrastructure previously associated with the Tortoiseshell actor profile for C2 orchestration.
  • Threat Profile and Operational Impact

    • Identified as one of the most active Iranian APT groups of 2026, exhibiting an accelerated operational tempo.
    • Increased persistence capabilities make the detection of unauthorized outbound tunnels significantly more difficult for SOC teams.
    • Evolution toward customized malware suggests a move away from off-the-shelf tools to avoid global threat intelligence tracking.
  • Defensive Actions and Mitigation

    • Enforce strict egress filtering to restrict outbound SSH (Port 22) traffic to known, authorized gateways.
    • Implement behavioral monitoring for long-duration SSH sessions and unusual data volume spikes to external IPs.
    • Deploy updated IOCs and YARA rules specifically targeting TWOSTROKE and Minifast backdoor variants.

Related posts

  1. techjacksolutions.com — Nimbus Manticore Expands Espionage Toolset With TWOSTROKE-Variant Backdoor and Reverse SSH Tunneling Utility
  2. feeds.feedburner.com — Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
  3. SC Media — Nimbus Manticore expands infrastructure and malware arsenal
  4. Group-ib
  5. Infosecurity-magazine
  6. Blog
  7. Broadcom

LINK COPIED TO CLIPBOARD